以下是qqq123123的帖子“主机入侵防御系统”进阶之注册表防护!
-----------------------------------------------------------------------------------------------------
01、DOS虚拟机程序
*\SYSTEM\CurrentControlSet\Control\WOW\*
02、Explorer防毒键值
*\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\*
03、Ini重定向加载项
*\Microsoft\Windows NT\CurrentVersion\IniFileMapping\*
04、LSA本地安全策略
*\SYSTEM\CurrentControlSet\Control\Lsa\*
*\SYSTEM\CurrentControlSet\Control\SecurityProviders\*
05、Rpc网络远程调用协议
*\SOFTWARE\Microsoft\Rpc\*
06、ShellExecuteHooks隐性启动
*\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks*\*
07、Windows安全中心
*\SOFTWARE\Microsoft\security center\*
08、Windows的文件校验
*\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer* 键值
AuthenticodeFlags
09、WinSock网络协议
*\SYSTEM\*controlset*\Services\WinSock*
10、安全模式
*\SYSTEM\*CurrentControlSet*\Control\SafeBoot\*
11、磁盘显示与隐藏
*\Enum\PCI\* 键值
ChannelOptions
12、打印服务
*\SYSTEM\CurrentControlSet\Control\Print\*
13、计划任务
*\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler*\*
14、浏览器侧边栏
*\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\*
15、浏览器插件
*\SOFTWARE\Classes\CLSID\* 键值
InprocServer32
*\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\*
*\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\*
16、浏览器工具栏按钮
*\Software\Microsoft\Internet Explorer\Extensions\*
17、浏览器工具条
*\SOFTWARE\Microsoft\Internet Explorer\Toolbar\*
18、浏览器默认搜索引擎劫持
*\Software\Microsoft\Internet Explorer\URLSearchHooks\*
19、浏览器启动页面
*\SOFTWARE\Classes\CLSID\*\shell\OpenHomePage\Command*
20、浏览器设置键值
*\Internet Explorer\Control Panel
*\Internet Explorer\Main
*\Internet Explorer\Main\*
*\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\*
21、浏览器通信协议
*\SOFTWARE\Classes\PROTOCOLS\Handler\*
22、浏览器协议前缀
*\SOFTWARE\Microsoft\Windows\CurrentVersion\URL*
24、命令行劫持
*\SOFTWARE\Microsoft\Command Processor\*
26、启动项相关键值
*\Software\Microsoft\Windows\CurrentVersion\Run
*\Software\Microsoft\Windows\CurrentVersion\Run\*
*\Software\Microsoft\Windows\CurrentVersion\RunOnce
*\Software\Microsoft\Windows\CurrentVersion\RunOnce\*
27、输入法加载项
*\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\*
28、网络协议组件
*\Software\Classes\Protocols\Filter\*
*\Software\Classes\Protocols\Handler\*
29、文件关联及打开方式
* 键值
Drive
*\*file\shell*\open\command
*\*ShowExt
*\CommCntrMaintenancePatch.CommCntrMaintenancePatch1
*\folder\shell\*ddeexec
*\http*\shell\open\command
*\InProcServer32
*\SOFTWARE\Classes\.*
30、文件夹选项菜单
*\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer 键值
NoFolderOptions
31、系统保护文件设置
*\SYSTEM\CurrentControlSet\Control\Session Manager 键值AllowProtectedRenames
32、系统登录脚本
*\SOFTWARE\Policies\Microsoft\Windows\System\Scripts\*
33、系统动态组件
*\Software\Microsoft\Active Setup\Installed Components\*
34、系统环境变量
*\SYSTEM\CurrentControlSet\Control\Session Manager\*
35、服务
*\*Services*\*
36、系统解码插件
*\SOFTWARE\Classes\CLSID\{083863F1-70DE-11D0-BD40-00A0C911CE86}\*
37、系统界面核心@用户环境
*\Software\Microsoft\Windows NT\CurrentVersion\Windows\*
*\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon*\*
38、系统配置策略
*\Software\Microsoft\Windows\CurrentVersion\Policies\*
39、系统启动配置
*\SYSTEM\CurrentControlSet\Control\BootVerificationProgram\*
40、系统图标资源
*\*Icon*
*\Control Panel\Desktop\WindowMetrics
41、系统自动播放
*\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun
*\System\CurrentControlSet\Services\Cdrom\Autorun
42、显示或隐藏文件
*\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\*
43、映像劫持
*\AeDebug\*
*\Image File Execution Options*
44、用户登陆框
*\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GinaDLL*
45、用户账户列表
*\SAM\*
46、终端服务
*\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\Terminal Server\*
*\SYSTEM\CurrentControlSet\Control\Terminal Server\*
47、终止程序设置
*\Control Panel\Desktop\ArtoEndTasks*
*\Control Panel\Desktop\HungAppTimeOut*
*\Control Panel\Desktop\WaitToKillAppTimeout*
*\SYSTEM\*ControlSet*\Control\WaitToKillServiceTimeout*
48、桌面项目设置
*\Software\Microsoft\Windows\CurrentVersion\Explorer\* 键值
HideDesktopIcons
49、组策略设置键值
*\SOFTWARE\Policies\Microsoft\Windows\Safer*